Add reproducible build system, native Unraid plugin, and WebUI
- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt, and fuse-overlayfs to verified upstream source checksums; SlackBuild recipes, scripts/build-packages.sh, checksums.sh, release.sh, and update-versions.sh implement the reproducible pipeline; GitHub Actions workflows build in a Slackware container and publish releases without committing any binaries. - plugin/podman.plg installs/updates/removes all eight packages (the seven components plus the plugin's own unraid-podman scaffolding package) via upgradepkg, using the official Unraid array-event hook mechanism (event/disks_mounted, event/stopping) instead of editing /boot/config/go. rc.podman and the sbin/ helper scripts implement storage creation, config seeding/sync, preflight checks, autostart with per-container Safe-Mode, and package verify/update/rollback. - webui/plugins/podman implements the Dashboard, Containers, Pods, Images, Volumes, Networks, Logs, Terminal, Compose, and Settings panels against the approved mockup (webui/mockups/prototype.html), talking to podman system service exclusively via PodmanClient.php (libpod REST API over the Unix socket), with two documented exceptions: Terminal's one-shot exec model and Compose's use of the podman compose CLI, since libpod has no REST equivalent for either. - docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions and honest current status (syntax-checked, unit- and integration-tested against fake sockets/servers; not yet run against a real Unraid/Podman/Slackware system). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Executable
+74
@@ -0,0 +1,74 @@
|
||||
#!/bin/bash
|
||||
# =============================================================================
|
||||
# packages/podman/podman.SlackBuild
|
||||
#
|
||||
# Builds the podman .txz package from upstream source (Go). Version and
|
||||
# checksum are pinned centrally in versions.env — see
|
||||
# scripts/lib/slackbuild-common.sh for the shared fetch/verify/package
|
||||
# helpers used below, and docs/ARCHITECTURE.md section 5 for why the
|
||||
# graphdriver build tags below are what they are (this project only ever
|
||||
# uses the overlay storage driver, see docs/ARCHITECTURE.md section 10).
|
||||
#
|
||||
# Requires (in the build environment): go >= 1.22, make, gcc, pkg-config,
|
||||
# libseccomp-dev. GPG signature verification support is intentionally left
|
||||
# out to keep the dependency footprint minimal for a from-scratch Slackware
|
||||
# build.
|
||||
# =============================================================================
|
||||
|
||||
set -eu
|
||||
|
||||
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||
# shellcheck source=/dev/null
|
||||
. "$REPO_ROOT/scripts/lib/slackbuild-common.sh"
|
||||
# shellcheck source=/dev/null
|
||||
. "$REPO_ROOT/versions.env"
|
||||
|
||||
VERSION="$PODMAN_VERSION"
|
||||
ARCH="$PKG_ARCH"
|
||||
BUILD="$PKG_BUILD"
|
||||
TAG="$PKG_TAG"
|
||||
|
||||
sb_init "podman"
|
||||
|
||||
tarball=$(sb_fetch_and_verify "$PODMAN_SRC_URL" "$PODMAN_SRC_SHA256" "podman-$VERSION.tar.gz")
|
||||
srcdir=$(sb_extract "$tarball")
|
||||
|
||||
# Apply any local patches (none currently — see packages/podman/patches/).
|
||||
for patch in "$CWD"/patches/*.patch; do
|
||||
[ -e "$patch" ] || continue
|
||||
echo "==> [podman] applying $(basename "$patch")"
|
||||
patch -d "$srcdir" -p1 < "$patch"
|
||||
done
|
||||
|
||||
cd "$srcdir"
|
||||
|
||||
# Build tags: exclude storage backends this project doesn't use (btrfs,
|
||||
# devicemapper — see docs/ARCHITECTURE.md section 10, overlay-only), exclude
|
||||
# systemd integration (Unraid has no systemd — see docs/ARCHITECTURE.md
|
||||
# "Rahmenbedingungen"), keep seccomp support.
|
||||
export BUILDTAGS="seccomp exclude_graphdriver_btrfs exclude_graphdriver_devicemapper containers_image_openpgp"
|
||||
export CGO_ENABLED=1
|
||||
export GOFLAGS="${GOFLAGS:--mod=mod}"
|
||||
|
||||
echo "==> [podman] make (BUILDTAGS=$BUILDTAGS)"
|
||||
make BUILDTAGS="$BUILDTAGS" GO_BUILD_FLAGS="-ldflags -s"
|
||||
|
||||
echo "==> [podman] make install into \$PKG"
|
||||
make install \
|
||||
DESTDIR="$PKG" \
|
||||
PREFIX=/usr \
|
||||
ETCDIR="$PKG/etc" \
|
||||
BUILDTAGS="$BUILDTAGS"
|
||||
|
||||
# We ship our own containers.conf/storage.conf/registries.conf/policy.json
|
||||
# templates (see config/) staged via plugin/podman.plg instead of upstream's
|
||||
# defaults, so drop the ones `make install` places under $PKG/etc to avoid
|
||||
# ambiguity about which file is authoritative on a running system.
|
||||
rm -rf "$PKG/etc/containers"
|
||||
|
||||
# No systemd units — Unraid has no systemd (see docs/ARCHITECTURE.md,
|
||||
# "Rahmenbedingungen"); process lifecycle is entirely owned by rc.podman.
|
||||
rm -rf "$PKG/usr/lib/systemd" "$PKG/lib/systemd"
|
||||
|
||||
sb_install_docs "$srcdir/LICENSE" "$srcdir/README.md"
|
||||
sb_make_package "$VERSION" "$ARCH" "$BUILD" "$TAG"
|
||||
Reference in New Issue
Block a user